arXiv:2604.17476cs.CRcs.AR2026-04

将虚拟现实头显的虚拟人重建任务安全外化,提升多用户并发数。

Privatar: Scalable Privacy-preserving Multi-user VR via Secure Offloading

论文配图:Privatar: Scalable Privacy-preserving Multi-user VR via Secure Offloading
图 1 · 摘自论文原文
  • 通过频域分块与水平分割,只外传低能量分量,降低计算负担和泄露风险。
  • 支持2.37倍更多并发用户,重建损失仅上升6.5%,能耗增加9%。
  • 结合分布感知噪声机制,既保障隐私又维持重建质量,适合多用户VR场景。

多用户虚拟现实虽能实现沉浸式交互,但每个头显需渲染大量参与者虚拟人,计算开销巨大,限制可扩展性。本文提出Privatar框架,将虚拟人重建任务从头显安全外化至同局域网内不可信设备,抵御数据截获攻击。核心思路是:虚拟人重建具有频域可分解特性,采用BDCT变换后,提出水平分割(HP)策略,将高能量频段保留在设备端,仅外传低能量成分,显著减少信息泄露。针对未聚合的多维信号,传统局部差分隐私需加过多噪声而牺牲可用性。观察到用户表情分布随时间缓慢变化且可在线追踪,提出分布感知最小扰动(DAMP),根据个体表情分布动态调整噪声,大幅降低对重建质量的影响,同时提供形式化隐私保证。实验表明,在Meta Quest Pro上,Privatar支持2.37倍并发用户,重建损失仅上升6.5%,能耗增加9%,在吞吐率-损失权衡上优于量化、稀疏化及本地构建基线。系统兼具可证明隐私与对经验及神经网络攻击的鲁棒性。

原文摘要 · Abstract (English)

Multi-user virtual reality enables immersive interaction. However, rendering avatars for numerous participants on each headset incurs prohibitive computational overhead, limiting scalability. We introduce a framework, Privatar, to offload avatar reconstruction from headset to untrusted devices within the same local network while safeguarding attacks against adversaries capable of intercepting offloaded data. Privatar's key insight is that domain-specific knowledge of avatar reconstruction enables provably private offloading at minimal cost. (1) System level. We observe avatar reconstruction is frequency-domain decomposable via BDCT with negligible quality drop, and propose Horizontal Partitioning (HP) to keep high-energy frequency components on-device and offloads only low-energy components. HP offloads local computation while reducing information leakage to low-energy subsets only. (2) Privacy level. For individually offloaded, multi-dimensional signals without aggregation, worst-case local Differential Privacy requires prohibitive noise, ruining utility. We observe users' expression statistical distribution are slowly changing over time and trackable online, and hence propose Distribution-Aware Minimal Perturbation. DAMP minimizes noise based on each user's expression distribution to significantly reduce its effects on utility, retaining formal privacy guarantee. Combined, HP provides empirical privacy against expression identification attacks. DAMP further augments it to offer a formal guarantee against arbitrary adversaries. On a Meta Quest Pro, Privatar supports 2.37x more concurrent users at 6.5% higher reconstruction loss and 9% energy overhead, providing a better throughout-loss Pareto frontier over quantization, sparsity and local construction baselines. Privatar provides both provable privacy guarantee and stays robust against both empirical and NN-based attacks.

虚拟现实隐私保护外化计算差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。